gmail-automation

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill's email automation purpose matches its capabilities, and the cited Rube/Composio relationship appears legitimate. However, Gmail access and OAuth are routed through a third-party intermediary rather than direct Google API integration, placing mailbox data and action authority in the hands of a remote hosted MCP/service. That is proportionate to the product's design but materially increases trust and data-flow risk, especially if users follow variants that add extra bridge software.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fgmail-automation%2F@efd0f8a0994181f2f7e9d02aa5a67a015eded1a6